Business App product entry
The historical orderingv1 record maps /my-products?id=678 to Business App. That ID is project-specific evidence, not a portable fixture or permission to open the page elsewhere.
The route reads id and requests the builder app, but mounting the generic app controller also requests themes and sites. If no matching site or theme exists, the fixed client source can issue creation requests automatically. Do not use a page visit, GET-only assumption, or screenshot session as a read-only verification method.
The returned base code selects the generic app experience. Basic settings can include mutable app fields, constants, images, colors, files, credentials, certificates, builds, downloads, and logs; Advanced settings are limited to a small fixed set of base codes.
The /my-products route is level-0-only. Sidebar discovery is separately limited to non-read-only level-0 sessions and populated from builder-app records; route, menu, record, and action authorization are not interchangeable.
Source-verified boundary
At the reviewed Dashboard SHA, the product page derives the app type from result.base.code: codes containing app render the generic app UI. Business App-specific learning links are selected only when the code is app_business_x; that label does not prove the historical ID currently resolves to that code.
For app_business_x, the fixed settings-tab list does not add an Advanced tab: Basic settings render directly. The page passes hideBuyBlocks=true, so the purchase, demo, store-download, and promotional blocks from the shared layout are not evidence of controls rendered in this entry.
The same mount can call GET /themes and GET /sites, then automatically call POST /sites and POST /sites/{siteId}/themes when prerequisites are absent. Basic settings always render app-field, signing-credential, and build surfaces and conditionally render constants, images, colors, and files. Their fixed handlers include app/base-action/base-constant updates, platform credential updates and local-certificate removal, build dispatch, build-log access, and artifact download. None were run for this documentation.
Do not open this entry to “check” it. Re-entry requires an isolated synthetic project, a known Business App fixture, immutable deployed-source receipts, intercepted requests, and explicit suppression of every write, build, signing material, certificate, download, log, provider, and external-link effect.
Before any later operation, verify the actual app ID, base code, record scope, displayed controls, request sequence, and authorization independently. A historical mapping or visible heading is not evidence that an action is safe or deployed.
Related guides: My products · Apps & Addons catalog